hardMultiple ChoiceObjective-mapped
300-410 Practice Question: Runs the following command on Router R1: R1# show…
A network engineer runs the following command on Router R1:
R1# show ip nat translations
Pro Inside global Inside local Outside local Outside global udp 192.0.2.10:1234 10.0.0.10:1234 203.0.113.5:53 203.0.113.5:53 tcp 192.0.2.10:5678 10.0.0.10:5678 198.51.100.20:80 198.51.100.20:80 --- 192.0.2.11 10.0.0.11 --- ---
R1# show ip nat statistics
Total active translations: 3 (0 static, 3 dynamic; 3 extended) Outside interfaces: GigabitEthernet0/1 Inside interfaces: GigabitEthernet0/0 Hits: 100 Misses: 0 CEF Translated packets: 100, CEF Punted packets: 0 Expired translations: 0 Dynamic mappings: -- Inside Source
[Id] ip nat pool POOL1 192.0.2.10 192.0.2.20 netmask 255.255.255.240
refcount 3 map-id 1 overload
[Id] ip nat inside source list ACL1 pool POOL1 overload
refcount 3
Based on this output, what is the problem?
⚠ Common exam trap
Cisco often tests the distinction between simple NAT and PAT by showing a translation entry without ports, leading candidates to incorrectly assume the pool is exhausted or that static NAT is in use, when the real issue is a misconfigured ACL or route-map that allows non-PAT traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The third translation is not using PAT, indicating a possible ACL or route-map misconfiguration.
The third translation lacks a protocol and port number, meaning it is a simple dynamic NAT entry without Port Address Translation (PAT). Since the pool is configured with the `overload` keyword, all translations should use PAT to share the pool addresses. The presence of a non-PAT translation indicates that the ACL or route-map used to match traffic for NAT is misconfigured, causing some traffic to be translated without port multiplexing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The third translation is not using PAT, indicating a possible ACL or route-map misconfiguration.
Why this is correct
The overload configuration should create PAT entries with protocol/port. The third entry without protocol suggests the traffic from 10.0.0.11 is not being matched by the same ACL or is using a different pool.
- ✗
The pool is exhausted because 192.0.2.10 is used twice.
Why it's wrong here
PAT allows multiple inside hosts to share the same global address; this is normal. Exhaustion would occur if all pool addresses were used without overload.
- ✗
The outside interface is misconfigured as inside.
Why it's wrong here
The statistics show correct interface assignment.
- ✗
The NAT translations are all static.
Why it's wrong here
The statistics clearly show 0 static translations.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,966 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.